Privacy Center

Privacy Policy

Effective Date: August 7th, 2018

Download the PDF

Here at Onshape, we consider the protection of your information to be a paramount responsibility that guides our day-to-day behaviors. In our Privacy Policy, we want to transparently convey to you our responsibilities vis-a-vis the information you generate when you use the Onshape service (the “Service”).

We will take reasonable steps to protect your privacy consistent with the guidelines set forth in this policy and with applicable U.S. and European Union laws. To be clear about the terminology we are using, when we say “personal information” in this Privacy Policy, we mean information that allows someone to identify or contact you, including, for example, your name, address, telephone number, e-mail address, username and IP address. When we use the phrase “anonymous information” in this Privacy Policy, we mean information that is not associated with or linked to your personal information. Anonymous information does not enable identification of or contact with individual persons. BY ACCESSING OR USING ONSHAPE, YOU ACKNOWLEDGE THAT YOU HAVE READ, UNDERSTAND, AND AGREE TO BE BOUND BY THIS PRIVACY POLICY AND OUR TERMS OF USE. IF YOU DO NOT AGREE TO THE POLICY AND TERMS OF USE, DO NOT USE THE SERVICE.

  1. Information We Collect and Receive

    When you access and use Onshape’s service, we collect and receive the following kinds of personal information:

    • Account and profile information: When you create your Onshape account, you are required to give us certain information (e.g., your email address and a password). We may ask for additional information from time to time in order to create a more robust user profile. This additional information is optional.
    • Billing information: If you purchase a paid subscription to Onshape or an application in our app store for which we perform billing, we collect credit card and additional payment-related information. This information is securely passed to our payment processing partners, and is not stored at Onshape.
    • Communications: When you communicate with us by sending us an email, we will collect and store any information that is contained in your communications with us.

    We collect the following types of anonymous information:

    • Log data: When you use Onshape, our system automatically records information including information that your browser sends whenever you visit a website or your mobile app sends when you are using it. This log data may include your Internet Protocol (IP) address, the address of the web page you visited before arriving at Onshape, your browser type and settings, the date and time of your request, information about your browser configuration and plug-ins, language preferences, and cookie data.
    • Device information: In addition to log data, we may also collect information about the device on which you are accessing Onshape, including what type of device it is, what operating system you are using, device settings, unique device identifiers, and crash data. Whether we collect some or all of this information often depends on what type of device you are using, and its settings.
    • Geo-location information: Internet Protocol (IP) addresses received from your browser or device may be used to determine approximate location and improve the service we provide to you.
    • Usage data: This is information about how you use the various capabilities and features of the Onshape service. We use this information to better understand opportunities to improve the quality of the service we provide to you.
    • Information from partners or other third parties: Onshape may receive information from partners or others to improve your experience. For example, Onshape’s Learning Center will provide us your course completion results so we can offer you more advanced training.

    Legal Basis for Processing Your Information

    We rely on the following legal grounds to process your personal information:

    • Performance of a contract – We need to collect and use your personal information to perform our agreement with you to deliver the Service as described in this Privacy Policy.
    • Consent – We may use or disclose some of your personal information such as precise location information or collect cookies as described in this Privacy Policy subject to your consent.
    • Legitimate interests – We may use your personal information for our legitimate interests to improve our products and services and the content on our Services. Consistent with our legitimate interests and any choices that we offer or consents that may be required under applicable laws, we may use technical information as described in this Privacy Policy and use personal information for our marketing purposes.
  2. Cookie Policy

    Onshape uses cookies or similar technologies to record log data and otherwise to make your interactions with the Onshape service easy and optimally effective. We use both session-based and persistent cookies.

    Cookies are small text files sent by us to your computer or other device and from your computer or other device to us, each time you visit our website. They are unique to your Onshape account or your browser or app. Session-based cookies last only while your browser or app is open and disappear from your device when you close your browser software or app or turn off your device. Persistent cookies remain on your device after you close your browser or app or turn off your device -- and last until you or your browser delete them or until they expire.

    Some cookies are associated with your Onshape account and personal information in order to remember that you are logged in. Other cookies are not tied to your Onshape account but are unique and allow us to do site analytics and customization, among other things. If you access Onshape through a browser, you can manage your cookie settings there, but if you disable cookies you may not be able to use Onshape effectively, or at all. Onshape sets and accesses our own cookies on the Service. In addition, we use third party vendors who set and access their own cookies to assist us with various activities (e.g., we use Google Analytics to help us monitor our website traffic). The use of these cookies by third parties is not covered by our Privacy Policy; the information generated by the cookies about your use of the Service (including your IP address) will be transmitted to and stored by the third parties. We do not combine the information generated through the use of third party providers with your personal information. You may refuse the use of cookies by selecting the appropriate settings on your browser, however, please note that if you do this you may not be able to use the full functionality of the Service.

  3. How We Use Your Information

    We use your information for the following:

    • Providing the Onshape service: We use information you provide to authenticate you, and enable you to use our cloud-based CAD, collaboration, storage and other services.
    • Compliance and investigations: We reserve the right to use data in connection with suspected inappropriate use, fraud, violations of Onshape’s Terms of Use, or any other activity that threatens to impede Onshape’s and/or its users’ ability to use the Onshape service efficiently and effectively.
    • Communicating with you: We will occasionally send you communications based on information you include in your profile, or your use of the Onshape service. You can manage the frequency and/or opt out of receiving these communications by changing your settings on the Service and/or clicking the “Unsubscribe” link at the bottom of each email. We also may send you service-related and administrative emails, for which you may not opt out.

    We may also use your personal information to create anonymous information records by excluding information that makes the information personally identifiable to you.

    Generally, we use anonymous information in statistical analysis to help us analyze patterns in the use of our Service. We may, through our use of cookies, keep you logged into our website, collect your click-stream data, tailor web content to you and personalize your experience on the website. We may also use your anonymous information to improve our internal operations, and notify visitors of updates to our Service.

  4. Your Choices
    • You have the ability to make your documents public or private in Onshape; and you have the ability to share public or private documents with other users.
      • By authoring a Public Document in Onshape, you agree to its accessibility by others. Any document you make public is neither private nor confidential and you should not have any expectation of privacy with respect to it.
      • Onshape will NEVER make your private content public. Reclassifying your Private Document as public will always require your affirmative action.
      • You also can reclassify any document you create from public to private at any time -- but Onshape cannot guarantee the confidentiality of any document that you had made public at any time in the past.
      • When you share a document in Onshape, anybody with whom you have shared the document may be able to use, reproduce, manipulate, distribute, display, transmit and communicate the contents of that document. If you do not want others to have those rights, do not share your documents in Onshape, or set your permissions accordingly. You are responsible for permitting access to documents which you are able to share.
    • You have the ability to comment on various aspects of Onshape’s service by contributing posts to Onshape’s Community Forum, participating in blog post discussion threads, etc. Any such commentary is neither private nor confidential and you should not have any expectation of privacy with respect to it.
    • If you terminate your subscription but do not delete your public and shared documents, we reserve the right but not the obligation to maintain the availability of those documents for all Onshape users (in the case of Public Documents) or users with whom any Private Document has been shared, together with information identifying you as the author of such documents. If you delete your documents before your subscription is terminated, your public and private shared documents will no longer be viewable by others.
    • The browser you use to access Onshape may provide you with the ability to control cookies or other types of local data storage.
    • Your mobile device may provide you with choices around whether and how location or other data is shared with us.
  5. Sharing and Disclosure

    As noted previously, Onshape’s culture emphasizes respect for your privacy. Consistent with that cultural value, we do not sell or rent your personal information to any third party except in the event of a change in control as described below. We limit our sharing of the information we collect and receive from you to the following circumstances:

    • Account Support: To provide you with customer support, our staff may need to share among themselves information you previously have provided to us.
    • Legal Compliance and Public Protection: We will share your information when we believe disclosure is reasonably necessary to comply with a law, regulation, legal request, or lawful request of a public authority; or to protect the safety, rights and/or property of the public or any person.
    • Integrity of Onshape’s Service: We will share your information as appropriate to detect, prevent, and/or address fraud, security or technical issues, or otherwise to protect Onshape and its user community.
    • Shared documents: If you are shared into a document that another Onshape user has made public, certain of your personally identifiable information will be visible to any other user who views that document.
    • Third Parties and Agents: We may employ third party companies or individuals to help us provide the Service or meet internal business operations needs, and they may process personal information on our behalf. For example, we may share data with a security consultant to help us get better at preventing unauthorized access or with an email vendor to send messages on our behalf. We also may share data with hosting providers, payment processors, marketing vendors, and other vendors and consultants who work on our behalf and under contractual promises of confidentiality. We maintain contracts with these providers restricting their access, use and disclosure of personally identifiable information in compliance with our obligations under this Policy.
    • Change in Control: Onshape may share your personal information in connection with or during negotiation of any merger, financing, acquisition or dissolution, transaction or proceeding involving sale, transfer, divestiture, or disclosure of all or a portion of our business or assets. In the event of an insolvency, bankruptcy, or receivership, personal information may also be transferred as a business asset. If another company acquires our company, business, or assets, that company will possess the personal information collected by us and will assume the rights and obligations regarding your personal information as described in this Privacy Policy.
    • App Store. When you purchase an application through our App Store, the developer of the application may seek your approval to access personally identifiable information covered by this Policy – and we will disclose such personally identifiable information to the developer only where you have provided such approval, and only where the developer has given us contractual assurances that they will provide at least the same level of privacy protection that is required by this Privacy Policy and that they will process personally identifiable information for limited and specific purposes consistent with the scope of approval you have provided. If we have knowledge that an application developer to which we have disclosed personally identifiable information covered by this Policy is processing such personally identifiable information in a way that is contrary to this Policy, we will take reasonable steps to prevent or stop such processing. In such case, the developer is liable for damages unless it is proven that we are responsible for the event giving rise to the violation.
    • Affiliates. Onshape may share your personal information to a parent company, any subsidiaries, joint ventures, or other companies under a common control (collectively, “Affiliates”), in which case we will require our Affiliates to honor this Privacy Policy.
    • Authorized Resellers and Partners. We may also share your personal information with our authorized resellers and partners for the purpose of further supporting your use of Onshape, and for co-marketing activities. All such authorized resellers and partners are required by Onshape to provide you with a means of opting out of some or all of their communications with you.
    • Aggregated and Non-Identifiable: Onshape may share aggregated or non-personally identifiable information with our partners or others in our sole discretion, including for business or research purposes.
    • Communicating With You: We will occasionally send you tailored communications based on information you include in your profile, or your use of the Onshape service. We also will send you service and administrative emails. You have an ability to opt out of certain of these communications as described above.

    With respect to the proprietary design data and other materials you generate when you use the Onshape service, we use such information within Onshape (1) as part of providing, maintaining, securing or modifying Onshape’s service regarding such data, (2) via automated tools intended to address or prevent a service, support or technical issue, (3) at your request or with your consent given to Onshape’s technical support team and/or other personnel as part of addressing or preventing a service, support or technical issue, or (4) in connection with legal obligations or proceedings and other activities described in further detail in Onshape’s Terms of Use. We also may share such information as set forth above.

    Service Visitors from Outside the United States: Onshape and its servers are located in the United States (among other geographies) and are subject to the applicable state and federal laws of the United States. If you choose to access or use the Service, you consent to the use and disclosure of information in accordance with this privacy policy and subject to such laws.

    Geographic Location

    For users within the United States, we process data in data centers located in the United States. We have adopted reasonable physical, technical, and organizational safeguards against accidental, unauthorized, or unlawful destruction, loss, alteration, disclosure, access, use, or processing of user data in our possession. We comply with state and federal laws governing the protection of personal information.

    For users within the European Union and Switzerland, we transfer data from the European Union to data centers located in the United States for processing. Such processing is performed in accordance with Regulation 2016/679 of the European Parliament and of the Council of April 27, 2016 on the protection of natural persons with regard to the processing of personal data and free movement of such data, known as the General Data Protection Regulation (“GDPR”). This includes the imposition of required safeguards with respect to accidental, unauthorized or unlawful destruction, loss, alteration, disclosure, access, use or processing of data. Transfers of European Union user data to processors in the United States are made in accordance with the EU-US and Swiss-US Privacy Shield Framework, as explained below.

    We comply with the EU-US Privacy Shield Framework and the Swiss-US Privacy Shield Framework as set forth by the US Department of Commerce regarding the collection, use, and retention of personal information from European Union member countries and Switzerland transferred to the United States pursuant to Privacy Shield.  We have certified that we adhere to the Privacy Shield Principles with respect to such data. If there is any conflict between the policies in this privacy policy and data subject rights under the Privacy Shield Principles, the Privacy Shield Principles shall govern. To learn more about the Privacy Shield program, and to view our certification page, please visit https://www.privacyshield.gov/

    If you are a resident of the EU or Switzerland, have the right to:

    • Request an accounting of all personal information that we possess that pertains to you in an electronically portable format (e.g., electronic copies of information attached to an email).
    • Request that we change any personal information that pertains to you.
    • Request that we delete any personal information that pertains to you.
    • Fully or partially withdraw your consent to the collection, processing, and/or transfer of your personal information.

    To request an accounting of your personal information, a change to your personal information, deletion of your personal information, or to withdraw your consent to the collection, processing, and/or transfer of your personal information, contact privacy@onshape.com via email. Once we have received notification that you withdraw your consent, we will no longer process your information for the purpose(s) to which you originally consented unless there are compelling legitimate grounds for further processing which override your interests, rights and freedoms or for the establishment, exercise or defense of legal claims.

  6. Changes to Privacy Policy

    We may change this Privacy Policy from time to time. We will prominently post any changes we deem to be material, and/or otherwise ensure that you are aware of them. If you continue to use Onshape after any changes are in effect, you will be deemed to agree to the revised policy.

  7. Third Party Websites

    This Privacy Policy addresses only our use and disclosure of information we collect from and/or about you on the Service. If you disclose information to others, or authorize us to do the same under this Privacy Policy, the use and disclosure restrictions contained in this Privacy Policy will not apply to any third party except as otherwise described above. We do not control the privacy policies of third parties, and you are subject to the privacy policies of those third parties where applicable. The Service may contain content or links to other websites that are not owned or controlled by us. We have no control over, do not review and are not responsible for the privacy policies of or content displayed on such other websites. When you click on such a link, you will leave our Website and go to another site. During this process, another entity may collect personal information or anonymous information from you. The Service may also contain links to other websites controlled by us but which operates under different privacy policies. Please review the privacy policy of any new site you visit.

  8. Dispute Resolution

    We assure compliance with the EU-U.S. and Swiss Privacy Shield Policy by fully investigating and attempting to resolve any complaint or dispute regarding the use and disclosure of personally identifiable information in violation of this Privacy Policy.

    Any questions or concerns regarding the use or disclosure of personally identifiable information should be directed to us at the address given below.

    We will respond to any inquiries or complaints within forty-five (45) days. In the event that we fail to respond or our response is insufficient or does not address the concern, we have registered with JAMS to provide independent third party dispute resolution at no cost to the complaining party. To contact JAMS and/or learn more about the company’s dispute resolution services, including instructions for submitting a complaint, please visit: https://www.jamsadr.com/eu-us-privacy-shield.

    If your complaint is not resolved through these channels, under limited circumstances, a binding arbitration option may be available before a Privacy Shield Panel.

    We will cooperate with the United States Federal Trade Commissions and any data protection authorities of the EU Member States (“DPAs”) in the investigation and resolution of complaints that cannot be resolved between us and the complainant that are brought to a relevant DPA.

    EU residents also have a right to lodge a complaint with a DPA. Each European Union member nation has established its own DPA; you can find out about the DPA in your country here: http://ec.europa.eu/justice/article-29/structure/data-protection-authorities/index_en.htm.

  9. Retention and Deletion

    We will only retain your personal information for as long as necessary to fulfill the purposes for which it was collected and processed, including for the purposes of satisfying any legal, regulatory, accounting or reporting requirements.

    In some circumstances, we may anonymize your personal information so that it can no longer be associated with you, in which case it is no longer personal information.

    It is our policy to retain personal information for 60 months once such personal information is no longer necessary to deliver the Service and to delete such personal information thereafter. This means that, if you close your account with us, we will delete personal information associated with your account after 60 months. Regarding other types of information we collect as described in this policy (Cookies, Log Files, Geo-Location Information, Device Identifiers), it is our policy to retain such personal information for 60 months and to delete such personal information thereafter.

  10. Questions or Concerns

    Any questions or concerns regarding the use or disclosure of your information, or any other matter related to this Policy, should be directed to Onshape, Inc., One Alewife Center Suite 130, Cambridge, MA 02140, Attention: Chief Financial Officer; or by sending an email to privacy@onshape.com.

    Our representative in the EU for personal data purposes is Foley Hoag AARPI, you can contact our representative at the following address: 153 rue du Faubourg Saint-Honoré
75008 Paris, France.